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Amendments to the Claims : 
This listing of claims replaces all prior versions and listings of claims in the application: 

Listing of Claims : 

1 . (Currently Amended) A method comprising: 

receiving, at a server, a request from a client to take an action with respect to an 
electronic document; 

retrieving a document identifier from the request; 

determining whether user authentication is needed based on the document identifier and 
the action; 

subsequent to retrieving the document identifier, sending information specifying an 
acceptable authentication procedure; 

receiving an authentication procedure update request from the client, the authentication 
procedure update request associated with the electronic document and requested by the client in a 
manner transparent to a current user of the client ; 

obtaining, at the server and in response to the authentication procedure update request, a 
software program selected based on the authentication procedure and comprising instructions 
operable to cause one or more data processing apparatus to perform operations effecting the 
authentication procedure; and 

sending the authentication software program to the client for use in identifying [[a]] the 
current user and controlling the action with respect to the electronic document based on the 
current user and document-permissions information associated with the electronic document. 

2. (Original) The method of claim 1, wherein obtaining the software program 
comprises requesting and receiving the software program from a second server. 



Applicant : Jonathan D. Herbach, et al. Attorney's Docket No.: 07844-0623001 / P568 

Serial No. : 10/699,165 

Filed : October 31, 2003 

Page : 3 of 12 



3. (Canceled). 

4. (Original) The method of claim 1 , wherein the software program uses an 
existing interface provided by the client to communicate authentication information to the server. 

5. (Original) The method of claim 1, further comprising: 

receiving credentials information from the client derived at least in part based on 
input obtained by the client using the software program; and 

communicating with a third party authentication server to authenticate the current 
user based on the credentials information. 

6. (Original) The method of claim 5, wherein the input obtained by the client 
comprises text input. 

7. (Original) The method of claim 5, wherein the input obtained by the client 
comprises biometric data. 

8. (Original) The method of claim 1, further comprising: 

receiving from the client an authentication receipt obtained by the client from a 
third party authentication server based on input obtained by the client using the software 
program; and 

verifying the current user with the third party authentication server using the 
authentication receipt. 

9-22. (Canceled). 



23. (Currently Amended) A system comprising: 
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a client that s e nds initiates a n authentication procedure update request to a server 
in a manner transparent to a current user of the client when an action is to be taken with respect 
to an electronic document local to the client , wherein the authentication procedure update request 
requests an authentication procedure associated with the electronic document ; 

the server that receives the authentication procedure update request, and in 
response to the client, the server obtains and sends a software program selected based on the 
authentication procedure and comprising instructions operable to cause one or more data 
processing apparatus to perform operations effecting [[an]] the authentication procedure; and 

wherein the client uses the auth e ntication software program to identify [[a]] the 
current user and control the action with respect to the electronic document based on the current 
user and document-permissions information associated with the electronic document, and 
wherein the action comprises an action taken with respect to the electronic document subsequent 
to opening the electronic document at the client. 

24. (Original) The system of claim 23, further comprises a second server that 
provides the software program. 

25. (Original) The system of claim 23, wherein the client includes a security handler 
that provides a server-communication interface to the software program. 

26. (Original) The system of claim 23, further comprising a third party authentication 
server that authenticates the current user based on credentials information derived at least in part 
based on input obtained at the client using the software program. 

27. (Original) The system of claim 26,wherein the client obtains an authentication 
receipt from the third party authentication server and forwards the authentication receipt to a 
server for verification. 
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28. (Original) The system of claim 23, wherein the server comprises: 
a server core with configuration and logging components; 

an internal services component that provides functionality across dynamically 
loaded methods; and 

dynamically loaded external service providers, including an authentication service 

provider. 

29. (Original) The system of claim 23, further comprising: 

a business logic tier comprising a cluster of document control servers, including 

the server; 

an application tier including the client comprising a viewer client, a securing 
client, and an administration client; and 

a load balancer that routes client requests to the document control servers. 

30-34. (Canceled). 

35. (Previously Presented) The system of claim 23, wherein the server obtains the 
software program by requesting and receiving the software program from a second server. 

36. (Canceled). 

37. (Previously Presented) The system of claim 23, wherein the software program 
uses an existing interface provided by the client to communicate authentication information to 
the server. 



38. (Previously Presented) The system of claim 23, wherein the server receives 
credentials information from the client derived at least in part based on input obtained by the 
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client using the software program, and communicates with a third party authentication server to 
authenticate the current user based on the credentials information. 

39. (Previously Presented) The system of claim 38, wherein the input obtained by the 
client comprises text input. 

40. (Previously Presented) The system of claim 38, wherein the input obtained by the 
client comprises biometric data. 

41 . (Previously Presented) The system of claim 23, wherein the server receives from 
the client an authentication receipt obtained by the client from a third party authentication server 
based on input obtained by the client using the software program, and verifies the current user 
with the third party authentication server using the authentication receipt. 



42. (Canceled). 



